Cryptography May Not Be Dead, But It Is on Life Support
blog.varonis.com
blog.varonis.com
Put another way--the FBI can sneak into my apartment any time they want by picking my lock, but I still lock my door.
The title is somewhere between misleading and dishonest. It's like saying that door locks are "dead" because burglars can go in the windows - in reality there's nothing wrong with the door locks, and the correct response is not to abandon the door locks but instead to secure the windows too (no pun intended).
The fact that there are side attacks is not a flaw of cryptography, rather it is a part of the environment in which it is practiced, and besides the attackers' workarounds are in principle subject to being defeated or avoided.
It may actually happen for quite a bit of people. I think your percentage is about people where it makes a difference in their life whether or not the Three Letter Agencies decrypt their traffic or not.
IT systems and networks have become so large and complex that vulnerabilities are everywhere. Your home computer may have a small enough attack surface by itself, but is constantly communicating with systems who don't - and much of your important data is kept in those anyway.
Note: As a fraction, the number you give for this is that it will happen to one in a billion people.
You are claiming that there are 8 people in the world that this outcome will happen to. While your general point may be true, I want to emphasise that this number is quite absurdly off. (It's off by at least two or three orders of magnitude.)
I always get particularly pissed because it makes the average person think it's no longer useful to encrypt their data, thus making them a vulnerable target. I wonder if it's a deliberately orchestrated disinformation campaign.
Quantum computing has larger implications than that. For instance, AES with 128-bit keys will need to be phased out since Grover's algorithm would allow a 2^64 time known-plaintext search. MD5 will likewise require 2^64 time to find a preimage, despite its resistance so far to non-quantum preimage attacks.
You should not discount that "only" asymmetric schemes based on DLP/IFP will be vulnerable, either. Much of our current key-exchange implementations do not have post-quantum strength at present.
Still, as you say, it is not "end of the world" status for cryptography. It will just require a lot of effort on the part of system builders to implement post-quantum constructions. The issue of backwards compatibility and widespread implementations will (as it always is) be a significant hurdle.
It's my experience, however, that the average person doesn't know or care about encrypting their data at all. It's almost certainly the opposite on a site like reddit or HN, but anecdotally, when my parents' friends (as an example) ask what I study and I say "cryptography," it's exceptionally hit-and-miss if they'll even know what I'm talking about. (A nontrivial portion of people think I've said "photography," actually!)
I've found that "encryption" is more widely-known than cryptography, but even then, it's been my experience that most (non-techie) people have no clue about it. But, I suspect that changes quite drastically given your social circle, area of the world you live in, and culture.
When I've given security talks I've always tried to compare things like air travel, which isn't 100% safe (planes do fall out of the sky) but is 100% "worth it" for most of us. And most of us won't be the focus of a government investigation.
So the reasoning that we can't make systems 100% secure, therefore security is dead, doesn't persuade me.
What will be interesting though is the use of cryptography to protect things like our pin numbers at the checkout line. That is an area that needs improvement right away.
Once my professor said the ATM machine in Japan randomized the order of the keys on the screen. I don't know how much effort it will require someone to upgrade the software to have a randomized keypad on the screen, but the risk of upgrading it is worth it.
And that probably wouldn't require a lot of computation either, since very few people would turn their phones off while going somewhere and then turn them on again. So the people who are doing this are smart enough to know that they can be tracked by their cell phones, but not smart enough to know that turning them off and on again calls a lot of attention to themselves.
So if you're going to a secret meeting that you don't want the NSA to know about, leave your phone at home.
This is the golden age for cryptography, thanks to education and hardworking people.
People are actively attacking our cryptographic knowledge and our implementations. As controversial as it may sound, if it weren't all the active attacks on our cryptographic infrastructure, we probably will be okay with RC4 and MD5. Of course we know they are weak and they are not reliable.
So let's thanks everyone, including the state-sponsored attackers.
This is golden age because we long know that relying on mathematical hardness assumptions is not safe. Maybe a decade later someone discover a theorem to factor large number very efficiently and then boom all the encrypted communications using RSA will be broken. We are slowly moving from that kind of dependencies. We think there are better ways to solve our encryption. Much like in 20th century the arm race gave rise to active advancement in all disciplines of engineering and science, cryptography is also growing.
Thanks to all the attackers out there we now know it is important to teach everyone about computer and web literacy. We know this should be part of education. In addition, we must make tools more accessible to users. At #realworldcrypto 2014 someone said PGP has been around what two decades? Why hasn't everyone in the tech community using it? Why are my non-geek friends not using it? Why am I not using it? Servers that retain user data or transfer user data should all be over HTTPS now. Implement 301 redirect on http end points and on HTTPS endpint add HSTS header. Implement Content-Security-Policy to harden what resources can be loaded on your website. Add X-Frame-Options to control whether you want your site to be frame/iframed or not. I can go on and on but you get the point. This is a long battle and not easy to fix.
Cryptography is not dead. What is dead is our assumption that we can rely on assumptions and that kind of dependency is going to harm us some time in the future. For how many more years? We don't know. It is possible no one can ever come up with an efficient algorithm to break factoring.
Yes. One problem in cryptography has to do with the key storage. I see that in the future HSM will be cheaper and people can enjoy that as opposed to a plaintext file in your $USER/.ssh/ directory. Look, cryptography is not silver bullet. You can't eliminate people from making mistake, but we can look at what things can be improved to make mistake fail quick and safely. Idea? Maybe instead of one key, we have multiple partial keys stored on multiple servers? But key management and key synchronization is going to be a headache. And look, if someone inject a malware in the network and has some insight knowledge of the network, there is very little you can do.
Never confuse NSA revelation means we must implement things so secure that we can't even tell Bob is Bob. We can't have 100% anonymity and we can't enforce that. The world needs interaction. The ability to choose is the right direction and I hope companies will start to realize that we don't live in the 80s anymore.
The hardest problem to solve is to tell whether the server is doing what it is said. People are working on verifiable search but what about whether site is actually hashing your password? Client-side encryption is important and mufti-identity remain to be solved. Personally, I'd like to see Persona widely used so I can just set up my own federated authentication server to authenticate my own email.
Again, as controversial as it may sound, knowledge exists because we can think and because we can think we have desire and goals. Knowledge doesn't grow out of the trees. The are always accidental and incidental. We don't start inventing things out of the thin air. I like the idea of knowledge as Yin-Yang. We don't start having cryptography because there is such a thing called cryptography. Because we want secret to be hidden and safe from evedropper, we invented substitution cipher schemes. Because we now have digital communication and we need to prevent MitM we need a better cryptography and this is why RSA and DHE are useful. We know SHA is never meant for hashing password because it's fast so we invent other kinds of cryptographically hard hashing algorithms like bcrypt and scrypt. If it weren't Miller's paper on fuzzing, we probably would neglect fuzzing testing and our unix command line tools will probably continue to fail hard. If it weren't NSA, how many of us would ever pay attention to the problem in OpenSSL and RNG? There is always a constant Yin-Yang interaction in the pursuit of knowledge. One nice property of security proof is that we always have to model the evil in our proof construction...
I want to quote this for emphasis.
One of the huge mistakes that drives our current despair is the unconscious ideal of a world where we aren't significantly interacting except through anonymous transactions. This isn't tenable. More importantly, this isn't human. Privacy is less about having security and more about convincing other people to avert their eyes. That's why the fault is on the NSA, not on, say, messaging protocols. Privacy is not sneaking into someone else's home. The burden of maintaining privacy is on the person who could violate it.
We can and should have pseudonymity.
"That's why the fault is on the NSA [..] The burden of maintaining privacy is on the person who could violate it."
Then we should abolish the police too. Criminals will just feel bad knowing they are at fault. Who is to blame, is irrelevant to how you address a problem.
We already do. We've always had pseudonymity.
> Then we should abolish the police too. Criminals will just feel bad knowing they are at fault. Who is to blame, is irrelevant to how you address a problem.
Don't forget journalists, whose entire purpose is breaking boundaries created by privacy.
I want to quote this for emphasis. ;)
Moreover, cryptography is more than just secret keys being kept secret.
For an example of cryptography which doesn't depend on secrecy, consider SNARKs (succinct non-interactive arguments of knoweldge): E.g. I can run a program and give you its output along with a compact proof that the output was the faithful output of the program. The size and complexity of verifying the proof is only a product of the cryptographic security level. Given cryptographic assumptions it is computationally infeasible for me to generate a fake proof.
The ability to prove the validity of execution in basically no more time than it takes the read the program being verified is a very powerful result of cryptography which doesn't depend on secrecy.
(The most efficient constructions of this currently need some secret data, but it's not a fundamental requirement)
If nothing else, Bitcoin as a protocol is a ray of hope for cryptography. If a digital crypto-currency ever becomes widely used, then crypto will become embedded in everyone's daily life (whether they're on Facebook and Gmail or not).
Public-Private Key Crypto is a concept that has only been in practice for less than 50 years. It has yet to be fully understood and implemented.
Securely-encrypted data is supposed to be indistinguishable from truly-random data --- this is the widely-used definition of security for encryption. If laws are in place requiring that a user reveal any decryption keys upon a court order, then a truly-random file will "look" encrypted and so you may be ordered to provide your key to decrypt the file. Of course, it is truly random, and there is no key, so you would be in contempt of court. Indeed, assuming secure encryption, there is no way to prove that a truly random file is not actually encrypted.
In an extreme case, where the state outlaws secrets entirely, possession of truly-random data will look like you are attempting to hide secrets.
And by "Computers can be compromised", this means computers also cannot be trusted to hold any sensitive data.
1. make key compromise harder, for instance require that an attacker compromise both your hardware and software to get your key,
2. limit the damage a key compromise can cause, for instance expire keys more often, randomly reissue keys,
3. and increase the speed with which you can recover from a key compromise. For example, the web PKI is completely compromised if a single CA key is compromised, but chrome can detect valid but forged google certs using key pinning and thereby alert the world. You can only use the stolen CA key to attack Google users once.
The security community is advancing on all three fronts.
Horrible example. Crypto, like every other secret keeping method comes down to trust. Who, and what do you trust to keep your secret.
So, one must assume that given enough interest, the governments will be able to compromise any system, and any data on these systems.
What if both him and his recipient do the same? Then you need physical access (and unnoticed physical access I'd add) to the offline computer to be able to decrypt right?
And physical access doesn't scale.
What if they swap Scheier's USB key (or drive) with one that will exploit the USB stack on his offline computer (disabling 'auto-mount' won't help you here)?
Yes, it's a physical access attack, but physical access to his person might be easier to achieve (while remaining unnoticed) than access to the offline computer.
If that's too cumbersome, one could always implement a simple teletype-like system with a low bitrate. Like an automatic machine that can physically press keys on a keyboard. Then remove every key except letters, numbers, shift and tab.
You could use a similar system or OCR to get data off the gapped machine.
Also, the offline computer can be physically compromised.
It won't have much processing power, but it will still be sufficiently fast to handle strong crypto on text messages.
Or, if they're really really paranoid, there is always an option to use old trusty TTL components.
Or do I have to build my own chips? And hopefully I didn't make an implementation mistake.
I don't think I would entrust my private keys to this outfit, sorry.
And then there's what happened to Target. Someone got to their machines, not physically, but with a trusted download. That paranoia now has to be carefully thought through by everyone who cares about their security...